⚡️ VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006).
Two attack vectors:
1. Remote attack on vCenter –
CVE-2026-59309: auth bypass via network access
CVE-2026-59310: directory traversal RCE
An exploit would allow control of entire ESXi infrastructure.
2. A VM-escapable set of two bugs –
CVE-2026-59310: vmxnet3 OOBW
CVE-2026-41703: core OOBR
These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user.
Diffing and exploiting (1) is straightforward and should be patched promptly.
Excited to finally share this ChatGPT vulnerability with everyone!
AgentForger: ChatGPT Cross-Site Agent Forgery
1-Click hijacks OpenAI's ChatGPT Workspace Agents and allows an attacker to forge an autonomous AI agent inside the victim's organization
Click link → Creates agent → Connects apps → Removes approvals → Adds persistence → Email C2 → Recon → Data theft → Impersonation → Wire fraud
We reported the vulnerability to @OpenAI through @Bugcrowd and OpenAI fixed it within four days. Thank you to the OpenAI team for such a quick fix!
I'm proud of this one and happy to be able to do it with such an incredible team at @zenitysec
Links to both blogs in the comments 👇
👉 Indirect Prompt Injection to DNS-based Data Exfiltration in macOS Terminal
🩹 Apple fixed the behavior that enabled the attack chain. thx!
Cheers to @LeonDerczynski@stokfredrik@davidgl whose research laid the groundwork for the PoC I put together 🙏
embracethered.com/blog/posts/202…
The best hackers I know aren't smarter than me.
They've just read more than me. Somewhere in their memory is the one obscure writeup that turns a dead end into a finding. Preview is that memory, on tap. For you, and for your agent.
-> rag.preview.is
Now point that capability gap at a monitoring pipeline.
Different model families process Unicode differently at the tokenizer level. We surveyed 12 frontier models across 61 Unicode categories and built the first cross-family blind-spot map.
Anthropic's tokenizer (both Haiku AND the Opus 4.8 flagship) strips 10 categories of invisible characters. OpenAI strips 2. Gemini, Llama, Mistral, DeepSeek, Grok? They strip ZERO.
That asymmetry is a covert channel. Hide a payload in characters the monitor's tokenizer deletes but the receiver's keeps:
Tag-char channel, Haiku monitoring GPT, n=30:
▪️ 100% receiver recovery
▪️ 0% monitor recovery
▪️ McNemar p ≈ 1.2×10⁻⁷
The monitor isn't dumb. It's physically blind. The bytes are gone before the model even runs. Hand the monitor the exact decode key and it STILL recovers 0%.
.@BobDaHacker compromised FIFA and was able to hijack their livestream cameras.
They considered replacing the FIFA cameras with the 1987 hit classic "Never Gonna Give You Up" by Rick Astley. Instead, they reported it and FIFA immediately fixed the issue
bobdahacker.com/blog/fifa-hack
omggg i made a joke about only 25 people using arch and all the fucking arch nerds appeared like UHMM ERRM SCHMELLY, ID LIKE TO INTERJECT FOR A MOMENT ,,, ASHCTULALY ARCH IS P POPULAR AND ITS USED FOR STEAM AND
holy cannoli bro, shut uppppp. its a joke. fucking hell
I don't usually like comics and stuff, no disrespect to them, but it's not my cup of milk. Regardless, some nerd on Xitter named @foolibuster has been making so much noise it's bleeding into my cybersecurity bubble.
He made this comic and I really want to share it with you all.
FuzzySecurity covers usermode exploitation, kernel exploitation, privilege escalation, persistence, credential theft, lateral movement, UAC bypass, heap internals, ROP chains, shellcoding, RFID hacking, and malware analysis. All free.
One of the few resources that takes you from basic buffer overflows all the way to kernel pool overflow and GDI bitmap abuse in a single series.
fuzzysecurity.com/tutorials.html
Author: @FuzzySec#ExploitDevelopment#ReverseEngineering#InfoSec
109 Followers 7K FollowingIf you don't want to Make America Great & Healthy Again, then you are a TRAITOR! GET OUT OF AMERICA! There is no other explanation! GOD1st!🚫PORN! 🚫CRYPTO
12 Followers 543 FollowingFound different beauties from all US states 😘
They are ready to meet
See nude photos before a date! Watching this https://t.co/VUt1GSepER
703 Followers 6K FollowingI’m clearing and honest lady I’m a billionaire I came from a wealthy family I came here to help the poor once not everyone opportunity is a scam 💯💯
10 Followers 398 FollowingGathered on the site of girls from all US states 😚
Ready for a 1 on 1 meeting
Some have naked profile photos! Watching this https://t.co/d0w9OFuPsK
25K Followers 27K FollowingA Hacker who is A Lover of People, and Life @RetroTwinz @Secbsd, @GrumpyHackers, @NovaHackers, @deadpixelsec @hacknotcrime Advocate @PositivelyBlue_ OSCP, OSWP
23 Followers 139 FollowingLove to share, like to make friends better than myself, treat others with sincerity, love high-quality life, be conservative, and yearn for freedom
1.6M Followers 2 FollowingWe're an AI safety and research company that builds reliable, interpretable, and steerable AI systems. Talk to our AI assistant @claudeai on https://t.co/FhDI3KQh0n.
67K Followers 697 Following• Homesick for a world that never existed. 🌿
• creating my fantasy island world world "Argenta" 🍃
• Art prints and original watercolors available 🌱
2K Followers 5 FollowingReaper Actual is a persistent, open-world shooter where squads fight to claim contracts, procure gear, and maintain bases to affect the living island of Marova.
1K Followers 17 FollowingYear 2 of the first con dedicated to exploring the offensive use of AI.
Hosted by RemoteThreat.
Oct 4-7, 2026 | Oceanside, CA
#OffensiveAICon
228K Followers 79 FollowingOne guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!
51K Followers 6 FollowingSign manufacturer in China with over 15 years of experience and UL listed. About collaboration,please contact
📩[email protected]
📞WA link:8615521052649
13K Followers 62 FollowingDrakantos is an MMORPG under development with more than 20 playable heroes, competitive PvP modes, and hundreds of PvE missions! #indiedev #pixelart #mmorpg
508K Followers 0 FollowingSentenced to die in prison. Pardoned by President Trump after spending 4,130 days (11+ years) in max security. Freedom is sweet!
4K Followers 1K FollowingDefend Tomorrow, Secure Today!
The internationally recognized Computer Emergency Response Team (CERT) for the Democratic People's Republic of Korea
10K Followers 664 FollowingHacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg